CVE-2023-28688: WordPress TH Variation Swatches plugin <= 1.2.7 - Cross-Site Request Forgery (CSRF) vulnerability
Published Dec 9, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in ThemeHunk TH Variation Swatches allows Cross Site Request Forgery.This issue affects TH Variation Swatches: from n/a through 1.2.7.
Affected Software
3 affected components
ThemeHunk TH Variation Swatches<=1.2.7
WordPress TH Variation Swatches<=1.2.7
ThemeHunk Variation Swatches Wordpress<1.2.8
Remediation
Information
Update the WordPress TH Variation Swatches plugin to the latest available version (at least 1.2.8).
Event History
Dec 9, 2024
CVE Published
via MITRE·11:31 AM
Data Sourced
via MITRE·11:31 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-28688?
CVE-2023-28688 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2023-28688?
To fix CVE-2023-28688, update the ThemeHunk TH Variation Swatches plugin to the latest version beyond 1.2.7.
3
What versions of TH Variation Swatches are affected by CVE-2023-28688?
CVE-2023-28688 affects TH Variation Swatches versions from n/a through 1.2.7.
4
What kind of attack does CVE-2023-28688 enable?
CVE-2023-28688 enables Cross-Site Request Forgery attacks.
5
Which software products are impacted by CVE-2023-28688?
CVE-2023-28688 impacts the ThemeHunk TH Variation Swatches and WordPress TH Variation Swatches plugins.